Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22391
HistoryJan 29, 2020 - 2:27 a.m.

XML Entity Expansion

2020-01-2902:27:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.003 Low

EPSS

Percentile

68.5%

feedgen is vulnerable to XML entity expansion. The library allows parsing of XML content into existing XML tree, which would allow an attacker to perform an XML bomb attack resulting in excessive resource consumption leading to an application crash.

CPENameOperatorVersion
feedgenle0.8.0

0.003 Low

EPSS

Percentile

68.5%